Openssh5.1p1 sftp file control

Bug #563216 reported by volksman
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
openssh (Ubuntu)
Triaged
Wishlist
Unassigned

Bug Description

DISTRIB_ID=Ubuntu
DISTRIB_RELEASE=9.10
DISTRIB_CODENAME=karmic
DISTRIB_DESCRIPTION="Ubuntu 9.10"

openssh 5.1-p1

Has support for chroot sftp users, however there is no way to control file permissions.

There is a patch here:

http://sftpfilecontrol.sourceforge.net/

That when applied adds a few items to sshd_conf to allow umask and a couple other overrides. This seems to have been accepted for openssh5.4. Would be great to see that patch implemented in 5.1p1 and even 5.3 (for Lucid).

Revision history for this message
Colin Watson (cjwatson) wrote : Re: [Bug 563216] [NEW] Openssh5.1p1 sftp file control

I plan to maintain a backport of 5.4p1 (or 5.5p1 once released) to Lucid
in a PPA. I haven't decided yet whether to maintain backports of
individual features like this, but I suspect I won't have time to do a
decent job of both.

Revision history for this message
volksman (v0lksman69) wrote :

A backport of 5.4 or 5.5 in Lucid would be fantastic. Then we can completely eliminate the need for scponly hacks.

Revision history for this message
Colin Watson (cjwatson) wrote : Re: [Bug 563216] Re: Openssh5.1p1 sftp file control

For Lucid, not in Lucid - Lucid itself will stay on 5.3p1.

Revision history for this message
Scott Moser (smoser) wrote :

Marking 'Triaged' and Wishlist based on Colin's comments.

Changed in openssh (Ubuntu):
importance: Undecided → Wishlist
status: New → Triaged
Revision history for this message
Peter Matulis (petermatulis) wrote :

I don't see any mention of umask in the sshd_config man page after installing 10.10 RC.

Revision history for this message
Peter Matulis (petermatulis) wrote :

OK, it's in the sftp-server man page.

Revision history for this message
Giovanni Bajo (giovannibajo) wrote :

Notice that OpenSSH added an option to change umask (which has always been possible through a wrapper script), but they still not support disabling chown and chmod, which is instead supported by the sftpfilecontrol patch.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.